VulnerabilityModified
CVE-2000-1111
Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.
MEDIUM 5.0EPSS 13.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 13.10% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/147914Vendor Advisory
- http://www.securityfocus.com/bid/2018Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5598
- http://www.securityfocus.com/archive/1/147914Vendor Advisory
- http://www.securityfocus.com/bid/2018Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5598
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.